Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,383 vulnerabilities found (page 1106 of 1616)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| f648a9ca-a72f-418e-bf1b-ad4ecc27d365 | < 2.8.8.1 |
MEDIUM | 5.3 | The Prevent Direct Access β Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposu… | — | wordfence |
| f6445bcc-b12d-419f-beca-8ee617465bf4 | < 2.35 |
MEDIUM | 5.3 | The Cookies and Content Security Policy plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… | — | wordfence |
| f6374cda-5aa2-4a2c-8d20-5641cfc33529 | MEDIUM | 5.3 | The WSM Downloader for WordPress is vulnerable to domain bypass due to insufficient hostname validation in the wsmd_user… | — | wordfence | |
| f62d28bd-fa33-4f0b-a116-5aacc05bfa3a | < 1.3.73 |
MEDIUM | 5.3 | The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.… | — | wordfence |
| f62a9ca0-7077-410f-b005-175348acd133 | < 3.3.0 |
MEDIUM | 5.3 | The SEO SIMPLE PACK plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2… | — | wordfence |
| f61b9de5-5c37-4efb-ad1c-006e9fc05bc2 | < 2.7 |
MEDIUM | 5.3 | The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capabili… | — | wordfence |
| f6092987-5f60-42ac-9636-e1e0a2c85147 | < 2.7.4 |
MEDIUM | 5.3 | The package http-cache-semantics is vulnerable to Regular Expression Denial of Service (ReDoS) in versions before 4.1.1 … | — | wordfence |
| f5fda67f-2bec-4439-8f7b-892fd89b9390 | < 7.0.2 |
MEDIUM | 5.3 | The Woocommerce OpenPos plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… | — | wordfence |
| f5f3f079-ccea-47a2-9441-29d8d8c77a5c | < 4.14.2 |
MEDIUM | 5.3 | The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… | — | wordfence |
| f5e490df-958c-4f3d-9ddb-68e82c03f495 | < 1.36 |
MEDIUM | 5.3 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… | — | wordfence |
| f5e400f8-35b4-4be4-bb00-c59e14ddd57f | < 23.1.3 |
MEDIUM | 5.3 | The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery β Upload, Vote, Sell via PayPal, Soc… | — | wordfence |
| f5e023d6-7a8c-4f18-941d-1a133d8a353e | < 4.0.50 |
MEDIUM | 5.3 | The Sendinblue for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence |
| f5dc2350-0dd3-4233-983f-3c7d294d18d1 | < 2.3.3 |
MEDIUM | 5.3 | The Product Attachment for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions … | — | wordfence |
| f5a9d976-5dee-437e-9fdf-1edffb8574b7 | MEDIUM | 5.3 | The Twitch Player plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… | — | wordfence | |
| f5a1c6bb-2054-40ad-b7fc-0a868b2c5eab | MEDIUM | 5.3 | The WooTumblog plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… | — | wordfence | |
| f58fac2a-d1f3-47f2-8abb-afe11ae2689a | MEDIUM | 5.3 | The Gift Cards for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… | — | wordfence | |
| f57dc0fe-07f3-457e-8080-fe530f6a9f01 | < 1.11.3 |
MEDIUM | 5.3 | The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… | — | wordfence |
| f5733ed6-a6f8-40f1-80b2-ab09fca02791 | < 4.3.4 |
MEDIUM | 5.3 | The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… | — | wordfence |
| f563b9ee-f33c-4d51-9db7-a3005c290fa7 | < 3.1.15 |
MEDIUM | 5.3 | The BigHearts theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… | — | wordfence |
| f563412d-5708-43c4-a44e-7645c5b4f835 | < 3.1.1 |
MEDIUM | 5.3 | The FlxWoo plugin for WordPress is vulnerable to Payment Bypass in all versions up to 3.1.1 (exclusive). This makes it p… | — | wordfence |
| f53700f8-9a9e-449c-8f7f-38724d74bd49 | < 2.4.11 |
MEDIUM | 5.3 | The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… | — | wordfence |
| f530dced-01bc-4555-b84f-705d6049956b | < 6.7.0.66 |
MEDIUM | 5.3 | The Quiz Maker Business plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … | — | wordfence |
| f52f1866-cd9d-4443-85c8-e0e7e50f3fbc | < 3.5.4 |
MEDIUM | 5.3 | The JetFormBuilder β Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized access due to a mi… | — | wordfence |
| f50c31df-56d0-4c34-a93c-56198fe91b36 | < 2.1.9 |
MEDIUM | 5.3 | The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file owne… | — | wordfence |
| f50bca0a-7089-4b4e-820f-d311fdb88cf1 | < 2.0.6 |
MEDIUM | 5.3 | WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.p… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →